Last updated 9 September 2026
Access is only through Google or Apple. No password is created, stored, or handled here, so there is none to be stolen. Whatever protection you have on that account — including two-step verification — protects this one too.
Every stored row carries the account that owns it, and the database enforces ownership on each request rather than trusting the app. A request for another member's ritual, CV, certificates, donations, attendance records or glossary terms returns nothing, even if it were deliberately crafted.
Certificate files are held in a private store, never a public web address. Each file sits in a folder belonging to your account, and viewing one creates a link that only works for you and expires after ten minutes.
All traffic is encrypted over HTTPS, and the database is encrypted on disk with regular backups by the hosting provider.
If you notice anything that looks like a weakness, please report it to the person running this site before mentioning it elsewhere.